28 Sep
|
EthicalHat
|
India
Experience: 8–12 Years
The Role
The AI SOC Manager will be responsible for the overall delivery and operational effectiveness of Security Operations Centre (SOC) services, including security monitoring, detection, incident response, threat hunting and continuous improvement. The role will lead SOC teams, oversee critical incident escalations and ensure that security operations meet agreed service levels, quality standards and client requirements.
The role will also drive practical adoption of AI-assisted security operations and automation to improve detection, triage, investigation and response workflows. The SOC Manager will work closely with clients, SOC leadership and technical teams to strengthen detection capabilities, improve operational processes and ensure appropriate governance of AI-enabled and automated SOC workflows.
Key Responsibilities
- Manage end-to-end SOC operations, including monitoring, detection, investigation, incident response, escalation management and service delivery across a 24×7 environment.
- Lead SOC Leads and Analysts, including work allocation, technical guidance, performance oversight, mentoring and capability development.
- Provide oversight and decision support for critical and high-severity security incidents, ensuring appropriate investigation, containment, escalation and stakeholder communication.
- Govern SIEM operations, including detection use cases, correlation rules, alert tuning, log-source coverage and continuous improvement of detection effectiveness.
- Drive threat hunting and detection engineering initiatives based on emerging threats, threat intelligence and frameworks such as MITRE ATT&CK.;
- Identify and implement appropriate AI-assisted and automated SOC workflows for alert enrichment, triage,
investigation, correlation and response, with suitable analyst validation and governance.
- Oversee SOAR playbooks and security automation initiatives to reduce repetitive analyst effort and improve consistency and response times.
- Review SOC performance through operational metrics, incident trends, SLA/KPI adherence, detection coverage and investigation quality; drive corrective and preventive actions where required.
- Act as a senior operational and technical point of contact for clients and internal stakeholders, leading service reviews, incident discussions and recommendations for security control improvements.
- Develop and maintain SOC processes, escalation procedures, incident response playbooks, operating guidelines and quality standards.
Skills & Experience
- 8–12 years of cybersecurity experience, with significant hands-on experience in SOC operations, incident detection and response, and experience leading SOC teams or managed security services.
- Strong understanding of SIEM architecture and operations, security monitoring, detection engineering, incident investigation, threat hunting and security analytics.
- Experience with enterprise SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, LogRhythm or equivalent technologies.
- Valuable working knowledge of EDR/XDR, SOAR, IDS/IPS, firewalls, DLP, vulnerability management,
identity security and related security controls.
- Robust understanding of attacker techniques, IOCs, behavioural detection and MITRE ATT&CK;.
- Experience managing major security incidents and coordinating technical investigation and response across multiple teams and stakeholders.
- Practical understanding of SOC automation, SOAR playbooks and AI-assisted security capabilities, including the risks and limitations associated with automated analysis and response.
- Experience defining and reviewing SOC metrics, SLAs/KPIs, detection coverage, incident trends and operational performance.
- Strong people management, mentoring and technical review capabilities, with the ability to develop SOC analysts and leads.
- Strong client-facing communication, reporting and stakeholder management skills, including the ability to communicate technical incidents and security risks to management audiences.
Preferred Qualifications
- Certifications such as CISSP, CISM, GIAC, CEH or relevant SIEM/SOC vendor certifications are preferred.
- Experience managing SOC operations within an MSSP, managed SOC or large enterprise security environment.
- Experience with detection engineering, SOAR implementation, security automation or AI-enabled capabilities within modern SIEM/XDR platforms will be an advantage.
Key Skills
- SOC Management
- Security Operations Center
- SIEM
- Incident Response
- Detection Engineering
- Threat Hunting
- Security Monitoring
- EDR
- XDR
- SOAR
- Security Automation
- AI-Assisted SOC
- MITRE ATT&CK;
- Threat Intelligence
- SIEM Use Cases
- Incident Management
- SOC Governance
- Client Management
Job Features
Job Category
SOC Manager
📌 AI SOC Manager (India)
🏢 EthicalHat
📍 India